IPSWDownload
iOSBeta
iOSiPadOSmacOStvOSvisionOS
Guides
iTunes3uToolsApple ConfiguratoriMazing
iOSBeta

Firmwares

iOSiPadOSmacOStvOSvisionOS

More

Guides

Tools

iTunes3uToolsApple ConfiguratoriMazing
IPSWDownload.com

The premier archive for Apple firmware downloads. Browse, search, and securely download official IPSW files for iPhone, iPad, Mac, Apple TV, and Apple Vision Pro.

Resources

  • iOS Firmware
  • iPadOS Firmware
  • macOS Firmware
  • tvOS Firmware
  • visionOS Firmware
  • Guides & Tutorials
  • About Us
  • Privacy Policy
  • Terms of Service
  • Contact Us

iOS & iPadOS

  • iOS 16 Firmware
  • iOS 15 Firmware
  • iOS 14 Firmware
  • iOS 13 Firmware
  • iOS 12 Firmware
  • iOS 11 Firmware
  • iOS 10 Firmware
  • iPadOS 16 Firmware
  • iPadOS 15 Firmware
  • iPadOS 14 Firmware
  • iPadOS 13 Firmware
  • iPadOS 12 Firmware

macOS & tvOS

  • macOS 13 Ventura
  • macOS 12 Monterey
  • macOS 11 Big Sur
  • tvOS 16 Firmware
  • tvOS 15 Firmware
  • tvOS 14 Firmware

Troubleshooting

  • Install IPSW on Mac/PC
  • Install IPSW on iPhone
  • Force DFU Restore iOS
  • Downgrade iOS Beta
  • How to Save SHSH Blobs
  • Apple Watch Restores
  • visionOS Restores
  • Universal Mac IPSW
  • View All Guides (57)

© 2026 IPSWDownload. All rights reserved.| Last Updated: August 9, 2026

Disclaimer: This website is an independent archive and is not affiliated with, authorized, maintained, sponsored, or endorsed by Apple Inc. "Apple", "iOS", "iPadOS", "tvOS", "macOS", "visionOS", "iPhone", "iPad", "Apple TV", "Mac", and "Apple Vision Pro" are registered trademarks of Apple Inc. All firmware links originate from official Apple servers.

Add to Preferred Sources
Twitter / XInstagram
Advanced • Updated August 14, 2026

Checkm8 Exploit: How Bootrom Vulnerabilities Work

Understand the famous Checkm8 exploit that permanently broke Apple's chain of trust on older iPhones, and how it relates to IPSW files.

Abhishek Roy
Abhishek RoyAuthor
iOS & Apple Specialist•6 min read•100% Free
Checkm8 Exploit: How Bootrom Vulnerabilities Work

Quick Answer

TL;DR: Understand the famous Checkm8 exploit that permanently broke Apple\'s chain of trust on older iPhones, and how it relates to IPSW files.

In 2019, a security researcher released "checkm8", an exploit that sent shockwaves through the iOS security community. It is an unpatchable vulnerability in the bootrom of hundreds of millions of Apple devices (from the iPhone 4S up to the iPhone X).

What is the Bootrom?

The bootrom (SecureROM) is the very first piece of code that runs when you turn on an iPhone. It is burned directly into the silicon processor at the factory. Because it is read-only memory (ROM), it can never be updated or patched by an IPSW firmware update.

The bootrom's job is to verify the digital signature of the next stage of the bootloader (iBoot). This creates Apple's "Chain of Trust."

How Checkm8 Breaks the Chain

Checkm8 exploits a "use-after-free" vulnerability in the USB code of the bootrom. By sending a carefully crafted USB request via a computer during DFU mode, an attacker can crash the bootrom and execute their own code before Apple's signature checks even run.

This allows jailbreak tools (like checkra1n and palera1n) to boot modified, unsigned firmware, completely bypassing Apple's security.

Why doesn't it work on the iPhone 11 and newer?

Apple identified the USB vulnerability during the manufacturing of the A12 Bionic chip (iPhone XS/XR) and fixed the code burned into the silicon. All devices from A12 onward are completely immune to checkm8.

Related Guides

If you are troubleshooting Apple firmware issues or managing device updates, explore our other step-by-step guides:

  • How to Extract Data from an IPSW Firmware File
  • How to Save SHSH Blobs for Future iOS Downgrades
  • What Happens if You Flash a Corrupted IPSW File?
Advertisement

Frequently Asked Questions

Can an OTA update fix a bootrom exploit?

No. Bootrom is physical hardware (Read-Only Memory). Software updates (OTA or IPSW) can only modify the flash storage, not the ROM.

Is Checkm8 untethered?

No. Because the exploit must be triggered over USB during the boot sequence, if the phone dies or reboots, it will boot up normally into stock iOS. You must connect it to a computer to re-trigger the exploit.

Can checkm8 bypass iCloud?

It can be used to temporarily hide the setup app, but a true iCloud Activation Lock bypass is impossible as the lock is server-side.
Abhishek Roy

Abhishek Roy

Expert in iOS firmwares, jailbreaking, and device troubleshooting. Delivering the best guides for Apple users.

Twitter / XGitHubInstagramWebsite
View All GuidesAdd on Google

Follow IPSWDownload

Add us to your Google source list for quick Apple update alerts.

Add on Google

Recent Articles

FutureRestore Guide: Using SHSH Blobs to Downgrade (Deep Dive)

Jul 9, 2026

iMazing vs iTunes: The Safest Way to Update iOS with an IPSW

Jul 9, 2026

3uTools Tutorial: How to Flash an IPSW and Retain User Data

Jul 9, 2026

What Happens if You Flash a Corrupted IPSW File?

Jul 9, 2026